New Malicious PyPI Packages used by Lazarus
2024-02-28 • JPCERT •
JPCERT/CC found Lazarus-linked malicious PyPI packages that imitated legitimate Python crypto libraries, including typosquatted names around pycrypto. The packages carried an XOR-encoded DLL in test.py that could be decoded and launched through __init__.py, then executed Comebacker with rundll32 and in-memory payload handling. Comebacker posted encoded host data to C2 endpoints such as chaingrown.com/manage/manage.asp and could receive and execute Windows executables in memory. JPCERT/CC tied the tooling to Lazarus through overlap with earlier Comebacker use against security researchers and code traits also seen in BLINDINGCAN, while noting package download counts in the hundreds to low thousands.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 63fb47c3b4693409ebadf8a5179141a… | 2024-02-21 | 2025-02-16 |
| DOMAIN | fasttet.com | 2024-02-21 | 2024-07-05 |
| IPv4 | 91.206.178.125 | 2023-11-04 | 2024-07-05 |
| DOMAIN | blockchain-newtech.com | 2023-12-08 | 2024-05-28 |
| DOMAIN | chaingrown.com | 2023-12-08 | 2024-05-28 |
| HASH | 173e6bc33efc7a03da06bf5f8686a89… | 2024-02-21 | 2024-02-28 |
| HASH | 956d2ed558e3c6e447e3d4424d6b14e… | 2024-02-21 | 2024-02-28 |
| HASH | e05142f8375070d1ea25ed3a31404ca… | 2024-02-21 | 2024-02-28 |
| HASH | 85c3a2b185f882abd2cc40df5a1a341… | 2024-02-21 | 2024-02-28 |
| HASH | 26437bc68133c2ca09bb56bc011dd1b… | 2024-02-21 | 2024-02-28 |
| HASH | 6bba8f488c23a0e0f753ac21cd83dde… | 2024-02-21 | 2024-02-28 |
| HASH | a8a5411f3696b276aee37eee0d9bed9… | 2024-02-21 | 2024-02-28 |
| HASH | 01c5836655c6a4212676c78ec96c0ac… | 2024-02-21 | 2024-02-28 |
| HASH | 8fb6d8a5013bd3a36c605031e86fd1f… | 2024-02-21 | 2024-02-28 |
| HASH | aec915753612bb003330ce7ffc67cfa… | 2024-02-21 | 2024-02-28 |
| HASH | a4e4618b358c92e04fe6b7f94a11487… | 2024-02-21 | 2024-02-28 |
| HASH | c56c94e21913b2df4be293001da84c3… | 2024-02-21 | 2024-02-28 |
| HASH | 60c080a29f58cf861f5e7c7fc5e5bdd… | 2024-02-21 | 2024-02-28 |
| HASH | b4a04b450bb7cae5ea578e79ae9d0f2… | 2024-02-21 | 2024-02-28 |
| HASH | 3ab6e6fc888e4df602eff1c5bc24f3e… | 2024-02-21 | 2024-02-28 |
| URL | https://fasttet.com/user/agency… | 2024-02-21 | 2024-02-28 |
| URL | https://blockchain-newtech.com/… | 2023-12-08 | 2024-02-28 |
| URL | https://chaingrown.com/manage/m… | 2023-12-08 | 2024-02-28 |